top of page

Privacy Policy

Introduction

BigBrain Health takes your privacy seriously. This Privacy Statement outlines BigBrain Health's practices regarding the collection, storage, and processing of Personal Information. It does not cover Protected Health Information (PHI), which is addressed in our HIPAA Notice of Privacy Practices.

We offer neurobehavioral assessments and scored results and may offer services by virtually connecting our users to clinical brain health specialists so that users may receive additional clinical services. We do this through our websites, including, but not limited to www.bigbrain.health (collectively, the “Sites”), our mobile application(s), and other electronic means such as video conferencing, chat, phone, and virtual events (together, “BBH Services”). The Services are owned by or are provided through BigBrain Health, Inc. (“BigBrain Health”).

 

BigBrain Health provides BBH Services through which you can access clinical services provided by a clinician (“Clinical Services”), research services provided by a researcher (“Research Services”), wellness services, and health information. BigBrain Health, Inc. contracts with separate clinical practices, non-profits, and companies whose qualified Clinicians provide Clinical Services to you (the “BigBrain Health Partner Clinicians”). These Clinicians, as well as independent clinicians, (each a “Clinician” or together, the “Clinicians”) provide Clinical Services to you. Research Services may be provided by BigBrain Health or by separate companies, non-profits, or individuals. 

 

Some of the information that we collect relating to the Assessment Services, Clinical Services, Research Services, and wellness services may be Protected Health Information (“PHI”) under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), such as your medical records that we receive from your healthcare provider, your lab results, your initial assessments, or device readings. PHI is covered by a separate policy called the {HIPAA Notice of Privacy Practices}. The HIPAA Notice of Privacy Practices describes how BigBrain Health uses and shares PHI and contains more information about your rights under HIPAA. This Privacy Statement may provide additional detail on how PHI is collected, processed, or stored, but if there is a conflict between this Privacy Statement and the HIPAA Notice of Privacy Practices with respect to PHI, the HIPAA Notice of Privacy Practices will solely apply.

 

We encourage you to read both the Privacy Statement and the HIPAA Notice of Privacy Practices carefully.  Please note, capitalized terms used in this Privacy Statement but not defined here have the definition given to them in the BigBrain Health Terms of Service.  

California Residents: See “Additional Information for California Residents” below for additional information about your rights.

 

[International Users: BigBrain Health is currently available only to users who are residents of the United States and are subject to U.S. privacy laws.  Accessing the services from outside the United States is not permitted under our Terms of Service.

This Privacy Statement is organized as follows:

What Personal Information Does BigBrain Health Collect?

Information You Provide To Us

Information Collected While Using Our Services

Information Collected from Other Sources

How Does BigBrain Health Use and Share Personal Information?

Use of Personal Information

Sharing Personal Information

Retention of Personal Information

How to Review, Modify, and Delete Personal Information

Right to Know/Access

Right to Modify

Right to Request Deletion

How to Exercise Your Privacy Rights

Additional Information for California Residents

How We Protect Personal Information

Tracking Technologies

Cookies and Other Tracking Technologies

Managing Your Tracking Technology Preferences

Regarding Targeted Advertising

Children’s Information

External Websites

Changes to This Privacy Statement

Contact Us

What Personal Information Does BigBrain Health Collect?

We may collect information that identifies, describes, or is personally related to you (“Personal Information”) in the categories below. We collect Personal Information from you, from your use of BBH Services, when you visit the Sites and mobile applications and from certain third-party sources.  By using BBH Services, and visiting the Sites and mobile applications, you agree that we can collect and use your Personal Information as described in this Privacy Statement.

Information You Provide To Us

BigBrain Health collects information that you provide to us, including when you enroll, give updates about your status, respond to a questionnaire or interactive assessment, or contact us. Some examples of this information include:

  • Contact or other Identifying Information, such as your name, address, email address, and phone number

  • Personal health information, such as age, sex, diagnoses, medications, lifestyle information (e.g., sleep patterns, physical activity levels, dietary habits), and family history;

  • Information related to your communications with BigBrain Health, including with the Clinicians;

  • Healthcare provider information (if you are a patient) or patient information (if you are a provider) or research participant information (if you are a researcher)

  • Professional licensure, organizational affiliation, license number, issuing state, and expiration date (if you are a provider or researcher)

Information Collected While Using Our Services

BigBrain Health may also collect certain information when you access, browse, and use BBH Services. This information is collected through the web apps and mobile apps used to deliver BBH Services. Some examples include:

 

  • Touchscreen interactions, gyroscope and accelerometer data, audio and video recordings of you. BigBrain Health will only collect audio and video recordings of user sessions needed for clinical evaluation and identity verification. Such recordings will be handled in accordance with this Privacy Statement and BigBrain Health's HIPAA Notice of Privacy Practices. 

  • Internet and other electronic activity data, such as technical information related to how you connect and use the services such as the date and time you access the service; how often you access BBH Services, and the internet address of the website from which you directly linked to BigBrain Health. 

  • Performance Information like log files, diagnostic or crash data, website/app performance logs and error messages or reports. 

  • Identifiers or geolocation data, such as Internet Protocol (IP) address and device identifiers; 

  • Data from Tracking Technologies, such as information from cookies, web beacons, tags or other tracking technologies, as further described below.

Information Collected from Other Sources

In connection with your use of the Services, we may combine or compare data we have collected from you with information collected from a third party. Some examples of information we may receive from a third party include information we may collect from your past, current or future health care providers, such as medical records, past or present diagnoses, previous treatments, general health, test results and reports, family medical history, and records of communications related to your health.

How Does BigBrain Health Use and Share Personal Information?

For information on how BigBrain Health Uses, Shares and Stores Personal Information that is Personal Health Information (“PHI”), see our HIPAA Notice of Privacy Practices.

Use of Personal Information

We may use the Personal Information we collect for one or more of the following business purposes:

  • To provide, personalize, improve, update, and expand BBH Services, including for:

    • Personalizing user experience;

    • Troubleshooting and customer support;

    • Developing new features and functionalities;

    • Product testing, development, and data analysis; and

    • Medical, scientific, statistical, and historical research

  • To communicate with you about BBH Services, including to:

    • Send administrative and service-related information (e.g., appointment reminders, updates to our terms or policies);

    • Provide customer and technical support;

    • Respond to your inquiries and concerns;

    • Provide you with information or request action in response to technical, security, and other operational issues;

    • Follow-up with you regarding your enrollment process and session status;

  • Provide customer support and gather feedback. 

  • To create de-identified information (for example, aggregated statistics) related to the use of the Services or for scientific research

  • To comply with laws and regulations, including to respond to law enforcement or a government request(s) as required by applicable law, court order, or governmental regulations and to monitor our compliance with those obligations

  • To protect the integrity and maintain the security of our Services or to enforce our Terms of Service

  • For any other purpose for which you may provide consent or as disclosed to you when you provide information to us.

 

When we use the term “de-identified information,” we mean information that is neither used, nor intended to be used, to identify an individual. We may use de-identified information without restriction and may share it with unaffiliated third parties.

Sharing Personal Information

BigBrain Health does not share your Personal Information with third parties except as described in this Privacy Statement, the {HIPAA Notice of Privacy Practices}, or with your additional consent (if required).  

 

Generally, BigBrain Health uses Personal Information to improve our science and usability and to advance research on brain function and clinical care.  

 

BigBrain Health may share Personal Information with the following categories of third parties for the following purposes:

 

  • Service Providers: We may share your Personal Information with service providers, such as contractors and other third parties we use to support our organization and provide us with services. These companies are subject to contractual obligations to implement appropriate technical and organizational measures to protect the confidentiality, security, and integrity of your Personal Information, in accordance with applicable laws. These companies include our cloud services infrastructure providers, vendors that assist us in marketing and consumer research analytics, fraud prevention, security, communications infrastructure providers, vendors that help us provide some support functions, like phone support or survey tools, and third party partners for analytics and advertising purposes; 

 

  • Corporate Affiliates: We may share your Personal Information with our subsidiaries, affiliates, partners, and associated organizations. 

  • Research Partners: We may share your Personal Information with research partners if you provide us with your express consent or if otherwise permitted by law. Research partners include commercial or non-profit organizations and researchers who work with those organizations that conduct or support scientific research, the development of therapeutics, medical devices or related material to treat, diagnose, or predict health conditions. 

  • Health Care Providers, Health Plans, and Similar Organizations: Personal Information that we create or obtain about you may be shared with health care providers, health plans, or other similar healthcare organizations for purposes of treatment, payment, and other healthcare operations, as permitted by law or pursuant to your consent.

  • Law Enforcement, Government Agencies or Other Third Parties, and Safety: We may voluntarily or be required to share your Personal Information if we believe it is reasonably necessary to: 

    • Comply with valid legal process (such as subpoenas, warrants, court orders, or other legal demands) or respond to lawful requests from government agencies or regulatory bodies

    • Enforce or apply the BigBrain Health Terms and Conditions 

    • Investigate fraud or protect the security or integrity of the Services 

    • Protect the rights, property, or safety of BigBrain Health, our employees, members, or users 

* If we disclose your Personal Information in this way, we will reasonably attempt to provide you with advance notice, unless we are prohibited from doing so. 

  • Corporate Transactions: If we are involved in a bankruptcy, merger, acquisition, reorganization, or sale of all or a portion of our assets, we may share or transfer your Personal Information as part of such corporate transaction.

  • As permitted or directed by you:  At your direction or with your permission.

Retention of Personal Information

BigBrain Health will retain the Personal Information you provide while creating your account and your profile until such time as you delete your account or you request deletion provided you are entitled to request deletion under applicable law. Any clinical records created as a result of your use of the Services (which constitutes Personal Health Information or medical information) will be securely maintained by BigBrain Health for a period that is no less than the minimum number of years such records are required to be maintained under applicable law (typically at least six years).  BigBrain Health may also retain certain information as reasonably necessary to comply with our legal obligations (including law enforcement requests), resolve disputes, maintain security, prevent fraud and abuse, as well as to comply with tax, securities, and regulatory compliance requirements.

How to Review, Modify, and Delete Personal Information

Some applicable laws provide individuals with specific privacy rights and you may have certain privacy rights with respect to the Personal Information we collect and maintain about you, such as the following:

Right to Know/Access

You may have a right to request access to your Personal Information and to be provided with a copy of certain information in a readily usable format, including:

  • The categories of Personal Information we collected about you;

  • The categories of sources from which we have collected your Personal Information;

  • Our business or commercial purpose for collecting or selling that Personal Information;

  • The categories of your Personal Information that we have shared with third parties;

  • The categories of third parties with whom we share your Personal Information; or,

  • The specific pieces of Personal Information we collected about you.

Right to Modify

You may have the right to request that we modify the Personal Information we have collected and that we maintain about you. To request to modify your Personal Information, email us at admin@bigbrain.health. We may request additional information from you in order to verify your identity and update your Personal Information per your request.

Right to Request Deletion

You may have the right to request that we delete the Personal Information that we have collected and that we maintain about you subject to applicable law. 

 

We may deny your request under certain circumstances, such as if we need your Personal Information to:

  • Provide you with the services you requested;

  • Complete the transaction for which the personal information was collected;

  • Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity;

  • Comply with a legal obligation; or

  • For other reasons permitted by applicable law.

 

If we deny your request for deletion, we will let you know the reason why. There may be some latency in deleting your Personal Information from our backup systems after it has been deleted from our primary production and development systems. Information that has been de-identified prior to your request can not be deleted. BigBrain Health may be subject to legal limitations with respect to the Personal Health Information that can be deleted.

How to Exercise Your Privacy Rights

If applicable, you may exercise your right to know/access and your right to request deletion twice a year free of charge. To exercise your rights to know/access and request deletion, please contact us at admin@bigbrain.health.  

 

You are responsible for the accuracy of the Personal Information you provide to us. We will take reasonable steps to verify your identity before processing your request. We will not fulfill your request unless you have provided sufficient information for us to reasonably verify that you are the individual about whom we collected Personal Information. When submitting your request, please provide us with your name and contact information for purposes of enabling us to begin verifying your identity. We may request additional information about you if needed to verify your identity. Unless you have previously provided us your Personal Information for another purpose, we will only use the Personal Information provided in the verification process to verify your identity or authority to make a request, and to track and document your request to meet our obligations. We do not discriminate against individuals for exercising any of the above privacy rights. These rights may not be available to you and certain exceptions and exemptions may apply that will limit your ability to exercise these rights.

 

Authorized Agents: If required under applicable law, you may use an authorized agent to submit a request to know/access or a request to delete on your behalf. Even if you use an authorized agent, you will still need to communicate directly with BigBrain Health to verify your identity and address. We require that your agent be registered to do business with the appropriate Secretary of State and/or that your agent provide us with a signed document from you that authorizes your agent to make the request on your behalf, and provide information necessary to verify your identity. To protect your Personal Information, we reserve the right to contact you directly if we have any questions or concerns about the request from your agent.

Additional Information for California Residents

If you are a California resident, California law provides you with additional rights regarding our collection, use and disclosure of your Personal Information under the California Consumer Privacy Act, as amended (“CCPA”), the Shine the Light law, and the Do Not Track law. The CCPA does not cover PHI collected by a covered entity or business associate that is governed by HIPAA. For information on how BigBrain Health uses and shares your PHI please refer to our HIPAA Notice of Privacy Practices. Additionally, under certain circumstances the CCPA will not apply to BigBrain Health.

 

Within the preceding 12 months:

  • We have collected the categories of Personal Information described above in “Personal Information We Collect” from the sources described therein for the purposes described in “How We Use and Share Your Personal Information.”

  • We have shared categories of Personal Information to Service Providers, Corporate Affiliates, and Other Third Parties (as described further in “How We Use and Share Your Personal Information”).

  • We have not sold your Personal Information.

How We Protect Personal Information

We take great care to protect the Personal Information we maintain about you. BigBrain Health has a broad information security program designed to protect your Personal Information using administrative, physical, and technical safeguards. We have measures in place to protect against inappropriate access, loss, misuse, or alteration of Personal Information under our control. For example, Personal Information is stored on encrypted servers. While we strive to protect your Personal Information, we cannot guarantee the security of information you provide to us. This is especially true for information you transmit to us via email because email may not have the security features that are commonly built into websites. To the fullest extent permitted by applicable law, we do not accept liability for unintentional disclosure of your Personal Information. You acknowledge that there are inherent risks associated with transmitting information over the internet, and that while we take reasonable measures to protect your Personal Information, we cannot guarantee its absolute security. Please be aware that we have no control over the information collected by your internet service provider or information that you disclose over a public network. We are not responsible for any information collected by third parties not within our control or how such information is used or maintained.

Tracking Technologies

We may use Tracking Technologies to improve the functionality of our website, understand user behavior, personalize content, and deliver relevant advertising such as cookies, web beacons or pixels, tags, scripts, and other storage technologies (collectively “Tracking Technologies”) to collect or receive information on the Sites. These Tracking Technologies may help us save your preferences, understand how you navigate through the Sites, and improve your experience.

Cookies and Other Tracking Technologies

Cookies are small data files that we transfer to your device to collect information about your use of the Sites. Cookies can be recognized by the website that downloaded them or other websites that use the same cookies. This helps websites know if your browsing device has visited them before. We may use both first-party and third-party cookies on the Sites for the following purposes: to make the Sites function properly, to improve the Sites, to track your interaction with the Sites, to enhance your experience with the Sites, to remember information you have already provided, to collect information about your activities over time and across third party websites or other online services in order to deliver content tailored to your interests; and to provide a secure browsing experience during your use of the Sites. Third-party cookies are subject to the respective privacy policies of those third parties. The length of time a cookie will stay on your browsing device depends on whether the cookie is a “persistent” or “session” cookie. Session cookies will only stay on your device until you stop browsing. Persistent cookies stay on your browsing device until they expire or are deleted. The following types of cookies may be used on the Sites:

 

  • Strictly Necessary Cookies. These cookies are essential because they enable you to use the Sites. For example, strictly necessary cookies allow you to access secure areas of the Sites and for us to provide the Sites. These cookies do not gather information about you for marketing purposes. This category of cookies would be essential for the Sites to work and they cannot be disabled.

 

  • Functional or Preference Cookies. We may use functional cookies to remember your choices so we can tailor the Sites to provide you with enhanced features and personalized content. For example, these cookies can be used to remember your name or preferences on the Sites. We would not use functional cookies to target you with online marketing. While these cookies can be disabled, this may result in less functionality during your use of the Sites.

 

  • Performance or Analytic Cookies. These cookies collect passive information about how you use the Sites, including webpages you visit and links you click. We would use the information collected by such cookies to improve and optimize the Sites. We would not use these cookies to target you with online marketing. You would be able to disable these cookies.

 

  • Targeting or Advertising Cookies. These cookies are used to drive online advertising that is relevant to you by building up a picture of what you are interested in from your use of the internet. The cookies can limit the number of times you see an advert and help to measure the effectiveness of any advertising. They remember that you have visited a website and this information may be shared with other organizations or advertisers. We may use these cookies in limited circumstances associated with our public-facing sites.

 

We may also use tracking technologies to collect “clickstream” data, such as the domain name of the service providing you with Internet access, your device type, IP address used to connect your computer to the Internet, your browser type and version, operating system and platform, the average time spent on the Sites, web pages viewed, content searched for, access times and other relevant statistics, and assign unique identifiers to the device or other credentials you use to access the Sites for the same purposes. Pages of the Sites and our emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags and single-pixel gifs) that permit us, for example, to count users who have visited those pages or opened an email and for other related website statistics (for example, recording the popularity of certain website content and verifying system and server integrity).

Managing Your Tracking Technology Preferences

Cookies.  When viewing the Sites, you can accept or reject the use of cookies. In addition, many browsers allow you to manage your cookie preferences at the individual browser level. You can set your browser to reject and/or delete some or all cookies. If you reject or delete cookies, please be aware that you may not be able to use some or all portions or functionalities of the Sites.

 

Do Not Track. Do Not Track" (DNT) is a feature in some web browsers that allows users to signal to websites that they do not want their online activities tracked. Currently, there is no universally accepted standard for how websites should respond to DNT signals. For this reason, the Sites do not currently process or respond to DNT signals. We are monitoring ongoing discussions and developments around DNT standards and will assess how to respond to such signals in the future. Since uniform standards for “DNT” signals have not been adopted, the Sites currently do not process or respond to “DNT” signals. 

 

Location Information. You may be able to adjust the settings of your device so that information about your physical location is not sent to us or third parties by: (a) disabling location services within the device settings; or (b) denying certain websites or mobile applications permission to access location information by changing the relevant preferences and permissions in your mobile device or browser settings. Please note that your location may be derived from your WiFi, Bluetooth, and other device settings. Please see your device settings for more information.

 

Analytics Tools. We may use tools such as Google Analytics, Facebook, and LinkedIn to help analyze how individuals use the Sites. We use these tools to analyze website traffic, user behavior, and trends, which helps us to improve our website and provide a better user experience. Such third parties may use cookies, APIs, and SDKs on our Sites to enable them to collect and analyze user and device related data and information on our behalf. These tools use cookies to collect information such as how often users visit the Sites, what pages they visit, and what other websites they used prior to coming to the Sites. We use the information we get to improve our Sites and to tailor the Sites to you.
 

 

  • Our Sites may utilize the Conversion Tracking Pixel service of Meta Platforms. This tool allows us to follow the actions of users after they click on a Facebook advertisement and allows us to record the efficacy of Facebook advertisements for statistical and market research purposes. The collected data remains deidentified which means we cannot see the personal data of any individual user. However, the collected data is saved and processed by Facebook and Facebook may be able to connect the data with your Facebook account and use the data for their own advertising purposes in accordance with Facebook’s Data Use Policy. Facebook Conversion Tracking also allows Facebook, and its partners, to show you advertisements on and outside Facebook. You can manage your preferences regarding how Facebook uses your data through your Facebook account settings.

By using our website, you agree to the collection and processing of your data by these analytics providers in accordance with their respective privacy policies.

Regarding Targeted Advertising

We may participate in online behavioral advertising, also known as interest-based advertising. This involves the collection of data about your online activities over time and across different websites to show you advertisements that are more relevant to your interests.

  • You have choices about how your data is used for online behavioral advertising. You can opt out of certain online behavioral advertising by visiting the Digital Advertising Alliance’s opt-out tool available at https://youradchoices.com/ and the Network Advertising Initiative’s Opt-Out Tool available at: https://networkadvertising.org/choices/.

Children’s Information

If you are between the ages of 13 and 16, do not use our Site or BBH Services unless your parent or legal guardian has provided explicit consent. We are committed to protecting the privacy of children and do not collect Personal Information directly from anyone who is, to our knowledge, under the age of 13. If you are under the age of 13, please do not provide any Personal Information to us through the Sites or Services. If you become aware that an individual under age 13 has provided Personal Information directly to us, please contact us as described in the “Contact Us” section, so that we can delete the information

 

A parent or guardian of children aged 13 to 18 years may create an account on behalf of their child, provided that the parent assumes full responsibility for the account and for the interpretation and use of any information provided through the Services. Further, the parent or guardian agrees to supervise their child’s use of the Services. Once a child reaches the age of 18, their Personal Information becomes theirs to control and the parent or guardian no longer has the ability to control the account.  Please note: currently BigBrain Health is not designed for use and is not available for individuals under the age of 16.  If you are between the ages of 13 and 16, do not use our Site or BBH Services unless permitted to do so by a parent or legal guardian.

External Websites

The Sites may contain links to other websites, including, but not limited to, investor relations sites, job applicant information gathering, assessment, and testing sites. These third party sites have their own privacy practices and measures to secure and protect your information. This Privacy Statement does not apply to any third party sites. We encourage you to review the privacy statement of any other third party website you may visit.

Changes to This Privacy Statement

This Privacy Statement is effective as of the date stated at the bottom of this Privacy Statement. We may change this Privacy Statement from time to time. We will notify you of any material changes to this Privacy Statement by posting a notice on the Sites or by sending you an email, as required by applicable law. Your continued use of the Sites or Services after the effective date of any changes constitutes your acceptance of the updated Privacy Statement.

Contact Us

BigBrain Health, Inc.
ATTN: Privacy
admin@bigbrain.health

2108 N St., Ste N

Sacramento, CA 95816

 

Last updated on and effective on: May 6, 2025

bottom of page